πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1585 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
018a6d18-5845-486f-b945-ee454d41374f MEDIUM 4.3 The Comment Date and Gravatar remover plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u… wordfence
0186dff1-28d3-46a4-bef2-83ec0400943d MEDIUM 4.3 The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
014392ee-4b24-4b81-954e-fc87727436ab
< 4.4.10
MEDIUM 4.3 The Starter Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
012e281d-7b9b-4ef1-ae8d-09984914a5e9 MEDIUM 4.3 The HivePress Claim Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check… wordfence
01170186-3384-494b-83d3-86ba3cf74837
< 1.9.4
MEDIUM 4.3 The Aiomatic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
01055be6-42ae-405f-9c8b-7acf5297867e
< 3.5.2
MEDIUM 4.3 The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl… wordfence
00fe71f4-365a-4151-90bd-a23a554c614c
< 2.4.4
MEDIUM 4.3 The Ultimate FAQ Accordion Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to… wordfence
00fcd671-5160-4c5b-bab8-aaa829fe25d4
< 2.0.9
MEDIUM 4.3 The RTMKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.… wordfence
00f65117-e8f7-41d8-bdf4-c1fab03e4792
< 2.1.3
MEDIUM 4.3 The ViaAds plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2.… wordfence
00f33681-7edb-40a8-a1b4-433765ef7585
< 1.2.3
MEDIUM 4.3 The Novelist plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. T… wordfence
00eed43d-9818-4ed8-b7b9-7e6aed9a9c64 MEDIUM 4.3 The Dreamer Blog theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
00ec2f57-48ee-49ea-ae8f-e7b24bf4535c
< 7.1.3
MEDIUM 4.3 The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
00ec14d4-d97b-40b1-b61b-05e911f49bb0
< 2.7.2
MEDIUM 4.3 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
00dd9a3c-a9f9-4fd2-9c93-0def42cec496 MEDIUM 4.3 The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
00d8124a-3bbc-42a0-afe1-e8e2dd9123fd
< 1.5.3
MEDIUM 4.3 The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
00b4b903-4682-458b-9681-751179460b75
< 2.0.40
MEDIUM 4.3 An issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It allows unauthorized profile and cover pic… wordfence
00aba7b3-4d4a-4aba-8e4e-2e8a928f6143
< 3.1.2
MEDIUM 4.3 The Leopard - WordPress Offload Media plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
00a95ae7-3c58-4e5e-aaef-c04d1dacf27f
< 4.2.3
MEDIUM 4.3 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an… wordfence
0099c700-e1af-4d97-a518-151a9139ea35 MEDIUM 4.3 Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capa… wordfence
009829be-5149-4d1a-ac81-ac2a2cfd9964
< 0.6.5
MEDIUM 4.3 The WPElemento Importer plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a… wordfence
00943fa8-6794-4b6b-adb8-8219482808d5 MEDIUM 4.3 The Event Organiser plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
0089bbd3-d3e4-4a13-b1f8-bb10bf18200c MEDIUM 4.3 The CodeablePress: Simple Frontend Profile Picture Upload plugin for WordPress is vulnerable to unauthorized access due … wordfence
007b3e8c-1a6d-4898-81f6-21fb0c4ecf3b MEDIUM 4.3 The WordPress Tabs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including… wordfence
0077b81c-c74d-4b1b-99b1-9a8f7032b2dc MEDIUM 4.3 The LWS SMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.1… wordfence
00380ab2-31cd-41af-9498-9eef32c2b6f0
< 1.31.1
MEDIUM 4.3 The Equalize Digital Accessibility Checker – Audit Your Website for WCAG, ADA, and Section 508 Accessibility Errors pl… wordfence
← Prev 1582 1583 1584 1585 1586 1587 1588 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top